Sample viewer

vx.netlux.org/Virus.DOS.Vole.503

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:44:32.885632686Z 26 PC: 12a9c | Set disk transfer address
2018-12-17T22:44:32.888438125Z 37 PC: 12aaa | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:44:32.891313415Z 37 PC: 12aae | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:44:32.893484813Z 78 PC: 12afa | Find first file
2018-12-17T22:44:32.900014688Z 61 PC: 12bcb | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:44:32.910704034Z 63 PC: 12bda | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:44:32.917519955Z 66 PC: 12be9 | Move file pointer
2018-12-17T22:44:32.918876633Z 66 PC: 12bf8 | Move file pointer
2018-12-17T22:44:32.920809353Z 64 PC: 12c04 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:44:32.924042205Z 66 PC: 12c10 | Move file pointer
2018-12-17T22:44:32.925189379Z 44 PC: 12c14 | Get time 0x12c14: mov byte ptr [bp + 0x1f7], dl
0x12c18: call 0x12c2e
0x12c1b: mov ah, 0x40
0x12c1d: mov cx, 0x1f7
0x12c20: lea dx, word ptr [bp + 6]
0x12c24: int 0x21
0x12c26: call 0x12c2e
0x12c29: mov ah, 0x3e
0x12c2b: int 0x21
0x12c2d: ret
0x12c2e: lea si, word ptr [bp + 0x33]
0x12c32: mov cx, 0x1a5
0x12c35: xor byte ptr [si], 0
0x12c38: inc si
0x12c39: dec cx
0x12c3a: jne 0x12c35
0x12c3c: ret
0x12c3d: add word ptr [bx], di
0x12c3f: aas
0x12c40: aas
2018-12-17T22:44:32.929914294Z 64 PC: 12c26 | Write file or device (Write 503 bytes on handle 5)
2018-12-17T22:44:32.944892445Z 62 PC: 12c2d | Close file
2018-12-17T22:44:32.954923304Z 79 PC: 12afa | Find next file
2018-12-17T22:44:32.958435711Z 61 PC: 12bcb | Open file (Filename = 'PRINT.COM')
2018-12-17T22:44:32.966997041Z 63 PC: 12bda | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:44:32.974187936Z 66 PC: 12be9 | Move file pointer
2018-12-17T22:44:32.976040245Z 66 PC: 12bf8 | Move file pointer
2018-12-17T22:44:32.979103178Z 64 PC: 12c04 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:44:32.982567675Z 66 PC: 12c10 | Move file pointer
2018-12-17T22:44:32.984713225Z 44 PC: 12c14 | Get time 0x12c14: mov byte ptr [bp + 0x1f7], dl
0x12c18: call 0x12c2e
0x12c1b: mov ah, 0x40
0x12c1d: mov cx, 0x1f7
0x12c20: lea dx, word ptr [bp + 6]
0x12c24: int 0x21
0x12c26: call 0x12c2e
0x12c29: mov ah, 0x3e
0x12c2b: int 0x21
0x12c2d: ret
0x12c2e: lea si, word ptr [bp + 0x33]
0x12c32: mov cx, 0x1a5
0x12c35: xor byte ptr [si], 0x3b
0x12c38: inc si
0x12c39: dec cx
0x12c3a: jne 0x12c35
0x12c3c: ret
0x12c3d: add word ptr [bx], di
0x12c3f: aas
0x12c40: aas
2018-12-17T22:44:32.98846995Z 64 PC: 12c26 | Write file or device (Write 503 bytes on handle 5)
2018-12-17T22:44:32.997847132Z 62 PC: 12c2d | Close file
2018-12-17T22:44:33.00687111Z 26 PC: 12b14 | Set disk transfer address
2018-12-17T22:44:33.009672151Z 9 PC: 12b20 | Display string (Could not find end pointer)
2018-12-17T22:44:33.022627012Z 9 PC: 12b35 | Display string (String= ' Inherit the Wind !!! ')